Description
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Remediation
References
https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39
https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4
https://security.netapp.com/advisory/ntap-20240621-0006/
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657
https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973
Related Vulnerabilities
CVE-2019-14862 Vulnerability in maven package org.webjars.bowergithub.knockout:knockout
CVE-2020-8203 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2018-1340 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2020-14326 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2021-23358 Vulnerability in maven package org.webjars.bower:underscore